How healthy is your infrastructure? One score, fully explained.
Denetta is a read-only IT infrastructure security audit platform developed by Bilgi Teknoloji: it audits FortiGate firewalls, switches and routers and a company’s domains without writing to any device, turns configuration into concrete findings with expert rule sets, and combines them into a single 0-100 Infrastructure Health Score justified rule by rule. It is multi-tenant for MSPs and hosted in Türkiye.
- Read-only, never writes
- Device access requires signed consent
- Hosted in Türkiye
Infrastructure Health Score
Sample view14 findings · 1 critical · 4 high
- Firewall58
- Network devices81
- Domain and email72
- Cloudout of scope
Categories you don’t use never lower your score.
165
expert audit rules
189
items in the measured FortiGate checklist
19
network device vendor profiles
443
outbound only — no inbound ports required
0
write commands sent to devices
Findings, not metrics: what does Denetta find?
RMM watches endpoints, NMS watches the network, CVE scanners watch vulnerabilities. Management has one question: “How healthy is our infrastructure?” Denetta answers it with findings that name the exact record, not with charts:
- Critical
Unrestricted management access open from the WAN
- Critical
FortiOS version affected by an actively exploited vulnerability
- High
Default SNMP community name ('public')
- High
No DMARC record
How does Denetta work?
We never ask you to open a port into your network; the collector only talks outbound, over 443.
- 01
Signed consent and scope
Scans that connect to a device start only with the customer’s signed and stamped written consent; the sites, IP blocks and domains to be audited are limited by that signature.
- 02
Read-only collection
Data comes from a file upload, the device’s read-only API or a collector in the customer segment; no path contains a write command.
- 03
Expert audit
Every category runs through its own expert rule set. Data that cannot be read is never counted as “passed”; it is reported as a “visibility gap”.
- 04
Score and remediation
The score comes with a rule-by-rule breakdown; remediation commands are shown in the device vendor’s syntax and are never executed.
What does it audit today, and what is next?
Firewall Audit
Expert-rule audit of FortiGate configuration: policy, management plane, VPN, HA, security profiles (121 rules).
FortiOS Vulnerability Matching
FortiOS version matched against CVE.org, CISA KEV and FIRST EPSS data; no exploit attempts.
Firewall Monitoring
Scheduled read-only scans, alerts on unannounced config changes and score trend; full backup archive in early access.
Network Device Audit
Read-only audit of switches and routers over SNMP/SSH; 19 vendor profiles, vendor-specific remediation text.
Domain and Email Security
Outside-in audit of SPF, DKIM, DMARC, MTA-STS, MX STARTTLS, web certificates, DNSSEC and domain registration.
Rule Cleanup
Unused rules and objects, shadowing, rule recertification workflow.
Microsoft 365 Tenant Audit
MFA enforcement, privileged roles, legacy authentication and external sharing, audited with read-only consent.
Compliance Packs
Gap report and evidence pack against KVKK, Law 5651, ISO 27001 and PCI DSS.
Access and Segmentation Analysis
Zone/segment access matrix and internet-exposed surface map.
Change Planning
Change request and approval workflow, verified on the next scan; nothing is sent to the device.
Law 5651 Access Log Archive
Tamper-evident archive of FortiGate access logs; does not replace the legal retention obligation.
Security Event Monitoring
FortiGate events; the first slice is VPN sessions and connected-time reporting.
Windows Server and Active Directory
FSMO, replication, DNS/DHCP consistency, patch compliance.
Servers, hardware and storage
Linux, iLO/iDRAC Redfish, RAID and SMART health.
Cloud
Azure, AWS and GCP audited through a read-only role.
IoT and cameras
Passive discovery, default-credential database matching and CVE matching.
Why do we say “never writes to a device”?
Because it isn’t a feature; it is the product’s identity: Denetta has no protection or intervention plane, and never will. Only show / get / display commands, SNMP GET/WALK and read-only API calls are used; vulnerabilities are detected by version ⇄ CVE matching, never by exploit attempts.
We also check whether the account you give us is truly read-only and restricted by source IP, and write the result into your report as a finding. The auditor’s access is audited too.
Does it replace your RMM?
No, it sits on top of it. Your Zabbix, NinjaOne or RMM stays in charge of real-time monitoring; Denetta adds a layer of periodic deep audits, scoring and expert analysis on top.
Quick questions
What is Denetta?
Denetta is an IT infrastructure health and security audit platform developed by Bilgi Teknoloji. It audits infrastructure layers such as firewalls, network devices and domains with read-only access, produces concrete findings with expert rules, and combines them into a single 0-100 Infrastructure Health Score.
Does Denetta make changes to my devices?
No. It only reads: show/get/display commands, SNMP GET/WALK and read-only API calls. It never writes to a device and never attempts an active exploit. The remediation commands it suggests are only displayed.
Do I need to open ports on the customer network?
No. The collector installed on the customer network only talks outbound, over HTTPS on port 443. For FortiGate you can also start with a single backup file, with nothing to install.
Let’s review your infrastructure together.
Let us show Denetta in a meeting with your own scenario and prepare a quote for your number of sites.